The March 2023 3CX incident was a cascading supply-chain attack: attackers used a trojanized X_TRADER installer to gain an initial foothold, then compromised 3CX build environments and distributed a malicious version of the 3CX desktop app. Mandiant attributed the activity to UNC4736 and assessed with high confidence that the cluster had a North Korean nexus; later campaign activity targeted cryptocurrency and defense organizations. That does not mean every 3CX customer—or every cryptocurrency firm—was compromised.
How the 3CX supply-chain attack started
The first known link in the chain was not a 3CX installer. Mandiant reported that an employee installed X_TRADER, an end-of-life trading application, on a personal computer. The installer had been downloaded from Trading Technologies’ website and contained VEILEDSIGNAL malware. MITRE ATT&CK dates the campaign’s first observed activity to November 2022; Mandiant identified the X_TRADER installer as the initial intrusion vector in its April 20, 2023 account. Mandiant’s incident analysis and MITRE’s campaign record describe this upstream compromise.
Using access gained through that first compromise, the attackers reached 3CX and compromised Windows and macOS build environments. The resulting malicious software was then distributed through 3CX’s own software channel. MITRE describes this as the first publicly reported case of one supply-chain compromise triggering another; that is MITRE’s characterization of the case, not a timeless claim that no earlier example could exist.
A supply-chain attack is especially difficult for users to spot because the code arrives inside software that appears legitimate. CrowdStrike observed malicious activity—including beaconing and second-stage payload deployment—emanating from the legitimate, signed 3CXDesktopApp binary. Its reporting covered activity on Windows and macOS. CISA’s March 30, 2023 advisory likewise relayed reports of a trojanized app and the possibility of multistage attacks. CrowdStrike’s findings and CISA’s advisory explain what made the downstream app dangerous.
#1 Best Overall
Exposure was not the same as confirmed compromise
Being exposed to an affected build means a device received or had access to the trojanized software. It does not, by itself, establish that the malware executed, that the device was successfully compromised, or that an organization suffered a confirmed breach. MITRE says only a subset of 3CX systems were affected, while describing subsequent targeting focused on cryptocurrency and defense sectors.
| Term | What it means in this incident |
|---|---|
| Exposure | A system had an affected 3CX software build. This alone does not prove malicious execution. |
| Observed malicious activity | Security telemetry showed behavior such as beaconing or deployment of a second-stage payload, as reported by CrowdStrike. |
| Sector targeting | Later campaign activity focused on cryptocurrency and defense organizations, according to MITRE; targeting does not establish that every organization in either sector was compromised. |
MITRE’s campaign record, created August 25, 2025 and checked October 4, 2026, says 3CX served more than 600,000 customers and 12 million users. Those figures describe the platform’s audience, not the number of infections. The reviewed reporting does not establish a verified total of cryptocurrency firms successfully compromised or a complete financial-loss figure.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
What “North Korean hackers” means here
The attribution is a qualified intelligence assessment, not a public identification of individual hackers. In 3CX’s April 11, 2023 summary of Mandiant’s interim findings, Mandiant attributed the activity to UNC4736 and assessed with high confidence that the cluster had a North Korean nexus. CrowdStrike used the label LABYRINTH CHOLLIMA, while MITRE associates the campaign with AppleJeus. These are different organizations’ tracking labels; they should not be treated as proven interchangeable names. 3CX’s summary of Mandiant’s findings, CrowdStrike’s attribution and MITRE’s campaign entry use those respective labels.
How the incident unfolded
| Date | What was reported |
|---|---|
| November 2022 | MITRE’s first-seen date for the campaign. Mandiant later described the X_TRADER installer as the initial route into the 3CX environment. |
| March 29–30, 2023 | 3CX said it received third-party reports on March 29. CISA published an advisory on March 30; CrowdStrike reported malicious activity from the signed desktop app. |
| April 1, 2023 | 3CX said its investigation with Mandiant was under way and gave users incident-period mitigation guidance. |
| April 11, 2023 | 3CX published Mandiant’s interim attribution to UNC4736 and high-confidence North Korean nexus assessment. The update discussed TAXHAUL/TxRLoader on Windows, COLDCAT as a downloader, and SIMPLESEA on macOS. It noted that TAXHAUL’s subsequent malware differed from GOPURAM referenced in Kaspersky reporting. |
| April 20, 2023 | Mandiant published its initial intrusion-vector findings. MITRE’s later campaign summary describes subsequent defense- and cryptocurrency-sector targeting and says only a subset of 3CX systems were affected. |
What 3CX and CISA advised during the incident
These were incident-period directions, not a current warning about every 3CX installation. On April 1, 2023, 3CX told Windows and Mac users to uninstall its Electron Desktop App, continue antivirus scans and endpoint detection and response (EDR) work using current signatures, and use its progressive web app (PWA) client instead. The company’s update said, “Switch to using the PWA Web Client App rather than Desktop App.” CISA urged organizations to consult technical reports and hunt for listed indicators of compromise. 3CX’s incident updates and CISA’s bulletin document that guidance.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Do not reuse those 2023 directions as a live alert without checking current 3CX advisories and the installed version. For organizations investigating a historical exposure, the useful distinction is whether an affected build was merely present or whether endpoint telemetry shows execution and downstream activity. CrowdStrike also advised removing the software until the vendor said later installers or builds were safe; that, too, was guidance issued in the incident period.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




